“Critical: Highly critical Impact: System access Where: From
remote Solution Status: Vendor Patch OS: Apple Macintosh OS X Apple
has issued a security update for Mac OS X iChat client. This fixes a
vulnerability, which can be exploited by malicious people to
compromise a vulnerable system. The problem is that links aren’t
properly validated before being opened. This can be exploited to
launch programs by embedding references to local resources. The
vulnerability has been reported…
"A remote iChat participant can send a "link" that references a
program on the local system. If the "link" is activated by clicking on
it, and the "link" points to a local program, then the program will
run. iChat has been modified so that "links" of this type will open a
Finder window that displays the program instead of running it."
Mac OS X security update fixes Safari vulnerability
Mac OS X security update fixes Safari vulnerability03/22/2005 05:04 PM Apple on Monday issued a security update for Mac OS X that fixes
several issues with the operating system, including a vulnerability in
the company's Web browser, Safari. The update also addresses several
other problems with the Mac OS X and Mac OS X Server.
Apples issues Security Update 2004-09-07 via Software Update
Apples issues Security Update 2004-09-07 via Software Update09/08/2004 03:45 AM Security Update 2004-09-07 delivers a number of security enhancements
and is recommended for all Macintosh users. This update includes the
following components:
CoreFoundation
IPSec
Kerberos
libpcap
lukemftpd
NetworkConfig
OpenLDAP
OpenSSH
PPPDialer
rsync
Safari
tcpdump
For detailed information on this Update, please visit this
website.